Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-05.2019 Ran by MRBS (04-05-2019 09:08:31) Running from C:\Users\MRBS\Desktop Windows 7 Home Premium Service Pack 1 (X64) (2011-06-12 22:27:47) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrador (S-1-5-21-2480086936-544305659-1921024182-500 - Administrator - Disabled) Convidado (S-1-5-21-2480086936-544305659-1921024182-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-2480086936-544305659-1921024182-1002 - Limited - Enabled) MRBS (S-1-5-21-2480086936-544305659-1921024182-1001 - Administrator - Enabled) => C:\Users\MRBS ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: ESET Security (Enabled - Out of date) {EC1D6F37-E411-475A-DF50-12FF7FE4AC70} AS: ESET Security (Enabled - Out of date) {577C8ED3-C22B-48D4-E5E0-298D0463E6CD} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: ESET Firewall (Enabled) {D426EE12-AE7E-4602-F40F-BBCA8137EB0B} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKLM-x32\...\uTorrent) (Version: 2.2.1 - ) Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated) Actualização do Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0816-0000-0000000FF1CE}_PROPLUS_{CCDE3C71-5F35-477F-BA90-1A399C91C10C}) (Version: - Microsoft) Actualização do Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0816-0000-0000000FF1CE}_PROPLUS_{CF0BC77F-1B63-44BF-BCFE-3A8CBB9077D1}) (Version: - Microsoft) Actualização do Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0816-0000-0000000FF1CE}_PROPLUS_{A1A8C49E-BB40-4852-853E-B5A1F6BB2A3C}) (Version: - Microsoft) Adobe Acrobat Reader DC - Português (HKLM-x32\...\{AC76BA86-7AD7-1046-7B44-AC0F074E4100}) (Version: 19.010.20099 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.6.0.6090 - Adobe Systems Incorporated) Adobe Flash Player 25 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 25.0.0.148 - Adobe Systems Incorporated) Adobe Flash Player 28 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 28.0.0.161 - Adobe Systems Incorporated) Advertising Center (HKLM-x32\...\{B2EC4A38-B545-4A00-8214-13FE0E915E6D}) (Version: 0.0.0.2 - Nero AG) Hidden Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.) Arquivo do WinRAR (HKLM-x32\...\WinRAR archiver) (Version: - ) Backup Manager Basic (HKLM-x32\...\{72B776E5-4530-4C4B-9453-751DF87D9D93}) (Version: 2.0.0.68 - NewTech Infosystems) Hidden Broadcom Gigabit NetLink Controller (HKLM\...\{A84DB02B-9C2B-4272-9D2D-A80E00A56513}) (Version: 14.0.2.3 - Broadcom Corporation) Bundled software uninstaller (HKLM-x32\...\bi_uninstaller) (Version: - ) <==== ATTENTION CCleaner (HKLM\...\CCleaner) (Version: 3.26 - Piriform) ConvertXtoDVD 2.2.3.258g (HKLM-x32\...\{BB406CEB-6207-4512-9BB2-89950DC9D6B6}_is1) (Version: 2.2.3.258g - VSO-Software SARL) ConvertXtoDVD 4.1.19.365 (HKLM-x32\...\{DB6AB705-C9BD-40E3-8929-2EA57F36A4FF}_is1) (Version: 4.1.19.365 - ) D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden DreamBoxEdit -- The one and only settings editor for your Dreambox (HKLM-x32\...\DreamBoxEdit) (Version: - ) DreamBoxTools v1.4.0.41 (HKLM-x32\...\{1ADE21D5-7A5E-4A2C-BA55-E88A21BE1953}) (Version: - ) DVD Shrink 3.2 (HKLM-x32\...\DVD Shrink_is1) (Version: - DVD Shrink) Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden ESET Security (HKLM\...\{3EB22EED-2263-4174-9F36-09BD15A7AEF8}) (Version: 12.1.34.0 - ESET, spol. s r.o.) ETDWare PS/2-x64 7.0.6.5_WHQL (HKLM\...\Elantech) (Version: 7.0.6.5 - ELAN Microelectronics Corp.) Ferramentas de Verificação do Microsoft Office 2013 - Português (HKLM-x32\...\{90150000-001F-0816-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden ffdshow v1.3.4532 [2014-07-17] (HKLM-x32\...\ffdshow_is1) (Version: 1.3.4532.0 - ) FileZilla Client 3.25.1 (HKLM-x32\...\FileZilla Client) (Version: 3.25.1 - Tim Kosse) Globe Visibility Connection Manager (HKLM-x32\...\{93D34EE3-99B3-4DB1-8B0A-0A657466F90D}) (Version: 1.0.0.1 - ) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 73.0.3683.103 - Google Inc.) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.34.7 - Google LLC) Hidden Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3003 - Packard Bell) ImagXpress (HKLM-x32\...\{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}) (Version: 7.0.74.0 - Nero AG) Hidden Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Graphics Media Accelerator Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2182 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 6.0.0.1179 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 9.6.2.1001 - Intel Corporation) IP-TV Player 49.3 (HKLM-x32\...\IP-TV_Player) (Version: 49.3 - ADSL Club Co Ltd) Java 8 Update 211 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180211F0}) (Version: 8.0.2110.12 - Oracle Corporation) JavaFX 2.1.1 (HKLM-x32\...\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation) Kodi (HKU\S-1-5-21-2480086936-544305659-1921024182-1001\...\Kodi) (Version: - XBMC-Foundation) Launch Manager (HKLM-x32\...\LManager) (Version: 4.0.14 - Packard Bell) Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden LogMeIn (HKLM-x32\...\{65179FD8-04C0-40A7-87FC-007F2CD5BF1E}) (Version: 4.1.1586 - LogMeIn, Inc.) LogMeIn Client (HKLM-x32\...\{D2300C4F-CC9B-4D00-BC53-B4C806A6C7AB}) (Version: 1.3.1675 - LogMeIn, Inc.) Malwarebytes Anti-Malware versão 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) Microsoft .NET Framework 4.7.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.03062 - Microsoft Corporation) Microsoft .NET Framework 4.7.2 (Português) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 2070) (Version: 4.7.03062 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Outlook Connector (HKLM-x32\...\{95140000-007A-0416-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation) Microsoft Office Outlook Connector (HKLM-x32\...\{95140000-007A-0816-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation) Microsoft Office Professional Plus 2007 (HKLM-x32\...\PROPLUS) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Project Professional 2013 (HKLM-x32\...\Office15.PRJPROR) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50918.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23918 (HKLM-x32\...\{dab68466-3a7d-41a8-a5cf-415e3ff8ef71}) (Version: 14.0.23918.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Movie Maker (HKLM-x32\...\{38F03569-A636-4CF3-BDDE-032C8C251304}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Movie Maker (HKLM-x32\...\{DD67BE4B-7E62-4215-AFA3-F123A800A389}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Mozilla Firefox 65.0.2 (x64 pt-PT) (HKLM\...\Mozilla Firefox 65.0.2 (x64 pt-PT)) (Version: 65.0.2 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 65.0.2.6995 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Nero 7 Premium (HKLM-x32\...\{62CB2326-9C09-42D8-AED9-077E8ED12070}) (Version: 7.03.1353 - Nero AG) Nero 9 Essentials (HKLM-x32\...\{c501e4e7-4c77-46aa-8cc5-173e31f062eb}) (Version: - Nero AG) Notepad++ (64-bit x64) (HKLM\...\Notepad++) (Version: 7.3.3 - Notepad++ Team) Opera Stable 58.0.3135.127 (HKLM-x32\...\Opera 58.0.3135.127) (Version: 58.0.3135.127 - Opera Software) Outils de vérification linguistique 2013 de Microsoft Office - Français (HKLM-x32\...\{90150000-001F-040C-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Packard Bell InfoCentre (HKLM-x32\...\Packard Bell InfoCentre) (Version: 3.02.3000 - Packard Bell) Packard Bell MyBackup (HKLM-x32\...\InstallShield_{72B776E5-4530-4C4B-9453-751DF87D9D93}) (Version: 2.0.0.68 - NewTech Infosystems) Packard Bell Power Management (HKLM-x32\...\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 5.00.3005 - Packard Bell) Packard Bell Recovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 4.05.3013 - Packard Bell) Packard Bell Registration (HKLM-x32\...\Packard Bell Registration) (Version: 1.03.3003 - Packard Bell) Packard Bell ScreenSaver (HKLM-x32\...\Packard Bell Screensaver) (Version: 1.1.0806.2010 - Packard Bell ) Packard Bell Social Networks (HKLM-x32\...\{64EF903E-D00A-414C-94A4-FBA368FFCDC9}) (Version: 2.0.3112 - CyberLink Corp.) Hidden Packard Bell Social Networks (HKLM-x32\...\InstallShield_{64EF903E-D00A-414C-94A4-FBA368FFCDC9}) (Version: 2.0.3112 - CyberLink Corp.) Packard Bell Updater (HKLM-x32\...\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.02.3001 - Packard Bell) QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6141 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30122 - Realtek Semiconductor Corp.) Resolume Arena 5.0.0 (HKLM-x32\...\Resolume Arena 5.0.0_is1) (Version: 5.0.0 - Resolume) Skype Click to Call (HKLM-x32\...\{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}) (Version: 8.5.0.9167 - Microsoft Corporation) Skype versão 8.43 (HKLM-x32\...\Skype_is1) (Version: 8.43 - Skype Technologies S.A.) software tmn (HKLM-x32\...\software tmn) (Version: 11.300.05.01.84 - Huawei Technologies Co.,Ltd) Songr (HKU\S-1-5-21-2480086936-544305659-1921024182-1001\...\Songr) (Version: 2.1 - Xamasoft) Suporte para Aplicações Apple (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) swMSM (HKLM-x32\...\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden TeamViewer 14 (HKLM-x32\...\TeamViewer) (Version: 14.2.8352 - TeamViewer) Telegram Desktop version 1.6.7 (HKU\S-1-5-21-2480086936-544305659-1921024182-1001\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 1.6.7 - Telegram Messenger LLP) Toolwiz Care (HKLM-x32\...\ToolwizCareFree) (Version: 2.1.0.4700 - ToolWiz Care) Unity Web Player (HKU\S-1-5-21-2480086936-544305659-1921024182-1001\...\UnityWebPlayer) (Version: 4.6.4f1 - Unity Technologies ApS) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for Skype for Business 2015 (KB4462207) 32-Bit Edition (HKLM-x32\...\{90150000-002A-0000-1000-0000000FF1CE}_Office15.PRJPROR_{E78636E8-8D6F-494B-917B-3F5D79693E95}) (Version: - Microsoft) VC80CRTRedist - 8.0.50727.6195 (HKLM-x32\...\{933B4015-4618-4716-A828-5289FC03165F}) (Version: 1.2.0 - DivX, Inc) Hidden Video Web Camera (HKLM-x32\...\{6D9021DC-CF1B-4148-8C80-6D8E8A8A33EB}) (Version: 0.5.37.3 - SuYin) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN) Welcome Center (HKLM-x32\...\Packard Bell Welcome Center) (Version: 1.02.3004 - Packard Bell) WinAVI Video Converter (HKLM-x32\...\WinAVI Video Converter 10.5_is1) (Version: - ZJ Computing,Inc.) Windows Live Sync (HKLM-x32\...\{587139F5-9B76-4D5A-94C6-76E6B219BF7F}) (Version: 14.0.8117.416 - Microsoft Corporation) WinPcap 4.1.1 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.1753 - CACE Technologies) Wondershare Filmora(Build 6.6.0) (HKLM-x32\...\Wondershare Filmora_is1) (Version: - Wondershare Software) Wondershare Helper Compact 2.5.2 (HKLM-x32\...\{5363CE84-5F09-48A1-8B6C-6BB590FFEDF2}_is1) (Version: 2.5.2 - Wondershare) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-2480086936-544305659-1921024182-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\MRBS\AppData\Local\Microsoft\OneDrive\19.062.0331.0003\amd64\FileSyncShell64.dll => No File CustomCLSID: HKU\S-1-5-21-2480086936-544305659-1921024182-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\MRBS\AppData\Local\Microsoft\OneDrive\19.062.0331.0003\amd64\FileSyncShell64.dll => No File CustomCLSID: HKU\S-1-5-21-2480086936-544305659-1921024182-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\MRBS\AppData\Local\Microsoft\OneDrive\19.062.0331.0003\amd64\FileSyncShell64.dll => No File ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => C:\Program Files\Notepad++\NppShell_06.dll [2017-02-12] (Notepad++ -> ) ContextMenuHandlers1-x32: [Cover Designer] -> {73FCA462-9BD5-4065-A73F-A8E5F6904EF7} => C:\Program Files (x86)\Nero\Nero 7\Nero CoverDesigner\CoverEdExtension.dll [2007-07-24] (Nero AG -> Nero AG) ContextMenuHandlers1: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Smart Security\shellExt.dll [2019-04-20] (ESET, spol. s r.o. -> ESET) ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2006-12-11] () [File not signed] ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2007-03-19] () [File not signed] ContextMenuHandlers2: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Smart Security\shellExt.dll [2019-04-20] (ESET, spol. s r.o. -> ESET) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll [2016-03-10] (Malwarebytes Corporation -> Malwarebytes) ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File ContextMenuHandlers4: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2006-12-11] () [File not signed] ContextMenuHandlers4-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2007-03-19] () [File not signed] ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2012-01-10] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation) ContextMenuHandlers6: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Smart Security\shellExt.dll [2019-04-20] (ESET, spol. s r.o. -> ESET) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll [2016-03-10] (Malwarebytes Corporation -> Malwarebytes) ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2006-12-11] () [File not signed] ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2007-03-19] () [File not signed] ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2011-06-12 20:06 - 2006-12-11 02:14 - 000043008 _____ () [File not signed] C:\Program Files (x86)\WinRAR\rarext64.dll 2010-10-26 21:03 - 2010-05-26 15:58 - 001545568 _____ (Suyin Optronics Corp. -> Suyin) [File not signed] C:\Program Files (x86)\VideoWebCamera\VideoWebCamera.exe 2019-02-14 18:50 - 2019-02-14 18:50 - 000452608 _____ (Intel Corporation) [File not signed] C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\2888a32922472ef15cba1faa54c47ee1\IAStorUtil.ni.dll 2010-09-13 08:57 - 2010-04-13 17:56 - 000032768 _____ (Intel Corporation) [File not signed] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\pt-PT\IAStorIcon.resources.dll 2010-09-13 08:57 - 2010-04-13 17:52 - 001046528 _____ (Intel Corporation) [File not signed] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IntelVisualDesign.dll 2010-09-13 08:57 - 2010-04-13 17:56 - 000004608 _____ (Intel Corporation) [File not signed] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\pt-PT\IntelVisualDesign.resources.dll 2017-03-13 23:34 - 2016-10-08 17:48 - 001506304 _____ () [File not signed] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\DAQExp.dll 2017-03-13 23:34 - 2016-07-21 11:54 - 000137728 _____ () [File not signed] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\CBSCreateVC.dll 2017-03-13 23:34 - 2016-10-08 17:49 - 000708608 _____ (Wondershare) [File not signed] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\CBSProducstInfo.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-2480086936-544305659-1921024182-1001\...\localhost -> localhost IE trusted site: HKU\S-1-5-21-2480086936-544305659-1921024182-1001\...\sharepoint.com -> hxxps://ipppt.sharepoint.com IE trusted site: HKU\S-1-5-21-2480086936-544305659-1921024182-1001\...\webcompanion.com -> hxxp://webcompanion.com ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:34 - 2009-06-10 22:00 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path: C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\QuickTime\QTSystem\ HKU\S-1-5-21-2480086936-544305659-1921024182-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\MRBS\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 8.8.8.8 - 8.8.4.4 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == If an entry is included in the fixlist, it will be removed. MSCONFIG\Services: AdobeARMservice => 2 MSCONFIG\Services: AGMService => 2 MSCONFIG\Services: AGSService => 2 MSCONFIG\Services: DsiWMIService => 2 MSCONFIG\Services: ePowerSvc => 2 MSCONFIG\Services: FLEXnet Licensing Service => 3 MSCONFIG\Services: GoogleChromeElevationService => 3 MSCONFIG\Services: GREGService => 2 MSCONFIG\Services: gupdate => 2 MSCONFIG\Services: gupdatem => 3 MSCONFIG\Services: IAStorDataMgrSvc => 2 MSCONFIG\Services: LMIGuardianSvc => 2 MSCONFIG\Services: LMIMaint => 2 MSCONFIG\Services: LMS => 2 MSCONFIG\Services: LogMeIn => 2 MSCONFIG\Services: MozillaMaintenance => 3 MSCONFIG\Services: NBService => 3 MSCONFIG\Services: Nero BackItUp Scheduler 4.0 => 3 MSCONFIG\Services: NMIndexingService => 3 MSCONFIG\Services: NTI IScheduleSvc => 2 MSCONFIG\Services: PLFlash DeviceIoControl Service => 2 MSCONFIG\Services: Skype C2C Service => 2 MSCONFIG\Services: TeamViewer => 2 MSCONFIG\Services: UNS => 2 MSCONFIG\Services: Updater Service => 2 MSCONFIG\startupreg: BabylonToolbar => "C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarsrv.exe" /md I MSCONFIG\startupreg: ExpressFiles => "C:\Program Files (x86)\ExpressFiles\ExpressFiles.exe" -tray MSCONFIG\startupreg: Facebook Update => "C:\Users\MRBS\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver MSCONFIG\startupreg: Google Update => "C:\Users\MRBS\AppData\Local\Google\Update\GoogleUpdate.exe" /c MSCONFIG\startupreg: Opera Browser Assistant => C:\Program Files\Opera\assistant\browser_assistant.exe MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun MSCONFIG\startupreg: ToolwizCareFree => C:\Program Files (x86)\ToolwizCareFree\ToolwizCares.exe ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [TCP Query User{BF70BEDB-2017-4F5C-9598-5CC3A511063C}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [UDP Query User{15F9F90F-21E1-437D-A8B5-F26DA308A572}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [TCP Query User{83E35903-2BF2-4843-AC42-967AA50FF0EC}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [UDP Query User{F992B1B6-1E8E-415E-A74B-C9BFAF89A1EF}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{4103CE63-E175-4E24-9DD3-63079184306D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{B7C8F0B5-45DA-4ED7-BC78-8AEC3EAEF0E8}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{CE255C86-A0BE-4F72-8704-7943A0089950}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{2D8AA557-8797-463B-B7A2-7AA08DD9B0AA}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{F47FAD6F-D5E1-4C70-8E4C-2FA9BB3C8E2E}] => (Allow) C:\Program Files (x86)\uTorrent\uTorrent.exe No File FirewallRules: [{3327597B-C9D3-4486-80F1-FF03D176B2C4}] => (Allow) C:\Program Files (x86)\uTorrent\uTorrent.exe No File FirewallRules: [{8FEB13BE-3DC5-4367-8E11-B1E4EE53D6AC}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe (Apple Inc. -> Apple Inc.) FirewallRules: [TCP Query User{4130E550-9DCB-4999-AEED-13C500B79216}C:\mr\skype portable\app\skype\phone\skype.exe] => (Allow) C:\mr\skype portable\app\skype\phone\skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [UDP Query User{5709059D-139F-4F92-89DB-407EAEFE7DA3}C:\mr\skype portable\app\skype\phone\skype.exe] => (Allow) C:\mr\skype portable\app\skype\phone\skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{917B8E78-A3C1-4091-AA76-161BE8F07754}] => (Allow) C:\Program Files (x86)\IP-TV Player\IpTvPlayer.exe (ADSL Club Co Ltd -> ADSL Club Co Ltd) FirewallRules: [{FF0A17BB-499E-4E3B-B193-18A5736305ED}] => (Allow) C:\Program Files (x86)\IP-TV Player\IpTvPlayer.exe (ADSL Club Co Ltd -> ADSL Club Co Ltd) FirewallRules: [{35DB509C-04B3-4B53-9279-05B367FC75B3}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH) FirewallRules: [{47C6449C-967F-4338-BFD3-DE58B3503BA8}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH) FirewallRules: [{2FBE8831-CA7D-469D-8084-0C0D88286A32}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH) FirewallRules: [{5CBB9D45-C546-47FE-831D-990A57CECD49}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH) FirewallRules: [{672D5ADA-EF8F-4D53-B9B5-2A36DB7789CD}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH) FirewallRules: [{F61C824D-CDE6-41A8-80CE-14B4376473AA}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH) FirewallRules: [{EA124EA9-4E63-4B79-95C5-78562F1B3931}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH) FirewallRules: [{12DA1CB5-D3CC-4BED-B9A9-38565B2B53FE}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH) FirewallRules: [{C13F5382-29FE-4B2C-8AE1-EB828272CF6E}] => (Allow) C:\Program Files\Opera\58.0.3135.118\opera.exe (Opera Software AS -> Opera Software) FirewallRules: [{69B63BBD-6CB5-4C88-BBEB-369E36F2BA0E}] => (Allow) C:\Program Files\Opera\58.0.3135.127\opera.exe (Opera Software AS -> Opera Software) FirewallRules: [{FCDD8624-90F5-47FF-B513-9575E14D5DEB}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe No File FirewallRules: [{B65419A5-A8C8-4B1F-99F2-D0DD6C2363C1}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe No File FirewallRules: [{75DFA4FC-03AA-4EE9-A596-EA165129F8EB}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google Inc.) FirewallRules: [{D65E745A-BA9A-4F40-B2E3-7655F5624709}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{87449BA1-E260-46F9-8699-597E16635245}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) ==================== Restore Points ========================= 19-04-2019 23:34:28 Operação de Restauro 20-04-2019 00:33:34 Windows Update 23-04-2019 13:28:15 Windows Update 29-04-2019 15:25:43 Windows Update 04-05-2019 08:55:21 Windows Update ==================== Faulty Device Manager Devices ============= Name: Teredo Tunneling Pseudo-Interface Description: Adaptador de Túnel Teredo da Microsoft Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (05/04/2019 09:03:49 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: O programa FRST64.exe versão 2.5.2019.0 deixou de interagir com o Windows e foi fechado. Para verificar se existem mais informações disponíveis sobre o problema, consulte o histórico de problemas no painel de controlo do Centro de Acção. ID do Processo: ae4 Hora de Início: 01d5024e97f84a57 Hora de Fim: 27 Caminho da Aplicação: C:\Users\MRBS\Desktop\FRST64.exe ID do Relatório: 17c728a2-6e43-11e9-9552-1c7508233b0f Error: (04/19/2019 11:19:13 PM) (Source: ESENT) (EventID: 215) (User: ) Description: WinMail (7128) WindowsMail0: A cópia de segurança parou porque foi interrompida pelo cliente ou a ligação ao cliente falhou. Error: (04/19/2019 11:19:06 PM) (Source: ESENT) (EventID: 215) (User: ) Description: WinMail (2696) WindowsMail0: A cópia de segurança parou porque foi interrompida pelo cliente ou a ligação ao cliente falhou. Error: (04/19/2019 12:17:47 PM) (Source: MsiInstaller) (EventID: 11316) (User: NT AUTHORITY) Description: Product: Avast Update Helper -- Error 1316. A conta especificada já existe. Error: (04/17/2019 03:13:16 PM) (Source: MsiInstaller) (EventID: 11316) (User: NT AUTHORITY) Description: Product: Avast Update Helper -- Error 1316. A conta especificada já existe. Error: (04/17/2019 03:08:06 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nome da aplicação com falha: firefox.exe, versão: 65.0.2.6995, carimbo de data/hora: 0x5c741256 Nome do módulo com falha: xul.dll, versão: 65.0.2.6995, carimbo de data/hora: 0x5c7413d8 Código de excepção: 0x80000003 Desvio de falha: 0x0000000004514681 ID do processo com falha: 0x4634 Data/hora de início da aplicação com falha: 0x01d4f52625cf07fa Caminho da aplicação com falha: C:\Program Files (x86)\Mozilla Firefox\firefox.exe Caminho do módulo com falha: C:\Program Files (x86)\Mozilla Firefox\xul.dll ID do Relatório: 38393725-611a-11e9-bf95-1c7508233b0f Error: (04/17/2019 02:13:15 PM) (Source: MsiInstaller) (EventID: 11316) (User: NT AUTHORITY) Description: Product: Avast Update Helper -- Error 1316. A conta especificada já existe. Error: (04/17/2019 01:13:53 PM) (Source: MsiInstaller) (EventID: 11316) (User: NT AUTHORITY) Description: Product: Avast Update Helper -- Error 1316. A conta especificada já existe. System errors: ============= Error: (05/04/2019 08:43:15 AM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Foi atingido o tempo limite (30000 milissegundos) ao aguardar por uma resposta de transacção por parte do serviço ShellHWDetection. Error: (05/04/2019 08:40:39 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Foi atingido o tempo limite (30000 milissegundos) ao aguardar pela ligação do serviço LogMeIn. Error: (05/04/2019 08:39:44 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: O serviço WindowsMangerProtect Service falhou o arranque devido ao seguinte erro: O sistema não conseguiu localizar o ficheiro especificado. Error: (05/04/2019 08:39:44 AM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: O serviço Áudio do Windows desligou-se ao iniciar. Error: (05/02/2019 11:06:47 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: O servidor {995C996E-D918-4A8C-A302-45719A6F4EA7} não foi registado no DCOM dentro do tempo de espera requerido. Error: (05/02/2019 03:14:54 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY) Description: Foi recebido o seguinte alerta fatal: 70. Error: (05/02/2019 03:10:45 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: O serviço WindowsMangerProtect Service falhou o arranque devido ao seguinte erro: O sistema não conseguiu localizar o ficheiro especificado. Error: (05/02/2019 03:10:36 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: O serviço Áudio do Windows desligou-se ao iniciar. Windows Defender: =================================== Date: 2019-04-20 00:22:37.607 Description: Windows Defender encontrou um erro ao tentar carregar assinaturas e irá tentar reverter para um conjunto de assinaturas em condições conhecido. Assinaturas Tentadas:Actual Código de Erro:0x80070002 Descrição do Erro:O sistema não conseguiu localizar o ficheiro especificado. Versão de Assinatura:0.0.0.0 Versão de Motor:0.0.0.0 Date: 2019-04-20 00:22:37.607 Description: Windows Defender encontrou um erro ao tentar actualizar assinaturas. Nova Versão de Assinatura: Versão de Assinatura Anterior: Origem de Actualização:Pasta de Actualização de Assinatura Tipo de Assinatura:AntiSpyware Tipo de Actualização:Delta Utilizador:NT AUTHORITY\SYSTEM Versão de Motor Actual: Versão de Motor Anterior: Código de Erro:0x80070002 Descrição do Erro:O sistema não conseguiu localizar o ficheiro especificado. Date: 2019-04-16 22:22:32.856 Description: Windows Defender encontrou um erro ao tentar carregar assinaturas e irá tentar reverter para um conjunto de assinaturas em condições conhecido. Assinaturas Tentadas:Actual Código de Erro:0x80070002 Descrição do Erro:O sistema não conseguiu localizar o ficheiro especificado. Versão de Assinatura:0.0.0.0 Versão de Motor:0.0.0.0 Date: 2019-04-16 22:22:32.851 Description: Windows Defender encontrou um erro ao tentar actualizar assinaturas. Nova Versão de Assinatura: Versão de Assinatura Anterior: Origem de Actualização:Pasta de Actualização de Assinatura Tipo de Assinatura:AntiSpyware Tipo de Actualização:Delta Utilizador:NT AUTHORITY\SYSTEM Versão de Motor Actual: Versão de Motor Anterior: Código de Erro:0x80070002 Descrição do Erro:O sistema não conseguiu localizar o ficheiro especificado. CodeIntegrity: =================================== Date: 2019-04-12 15:49:56.320 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\kernel32.dll because the set of per-page image hashes could not be found on the system. Date: 2017-09-29 14:59:42.727 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\ProgramData\ESET\ESET Smart Security\updfiles\base_nonnups\nod32F6.dll.nup.raw because the set of per-page image hashes could not be found on the system. Date: 2017-09-29 14:59:42.022 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\ProgramData\ESET\ESET Smart Security\updfiles\base_nonnups\nod32F6.dll.nup.raw because the set of per-page image hashes could not be found on the system. Date: 2017-09-29 14:59:41.372 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\ProgramData\ESET\ESET Smart Security\updfiles\base_nonnups\nod32F6.dll.nup.raw because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== BIOS: Packard Bell V1.07 09/27/2010 Motherboard: Packard Bell EasyNote TK85 Processor: Intel(R) Core(TM) i3 CPU M 370 @ 2.40GHz Percentage of memory in use: 92% Total physical RAM: 3766.71 MB Available physical RAM: 269.18 MB Total Virtual: 7531.57 MB Available Virtual: 2430.09 MB ==================== Drives ================================ Drive c: (Packard Bell) (Fixed) (Total:452.66 GB) (Free:210.9 GB) NTFS \\?\Volume{29a51e4c-e13a-11df-82ab-806e6f6e6963}\ (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS \\?\Volume{29a51e4b-e13a-11df-82ab-806e6f6e6963}\ (PQSERVICE) (Fixed) (Total:13 GB) (Free:1.53 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 88AEDB92) Partition 1: (Not Active) - (Size=13 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=452.7 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================